Impact
In the Linux kernel, the blk‑iolatency subsystem incorrectly retains a delay flag when a latency policy is removed. The bug causes use_delay to stay set, making blkcg_congested() always return true for every task in the affected cgroup. This results in severe throttling of both read and write operations, producing a denial‑of‑service effect for workloads that rely on the cgroup. The flaw arises from improper state cleanup when freeing policy data and was fixed by ensuring the delay flag is cleared in iolatency_pd_free().
Affected Systems
The vulnerability affects all Linux kernel releases that include the blk‑iolatency implementation before the corrective patch. No vendor‑specific product or version ranges are supplied, so any system running an unpatched kernel that exposes blk‑iolatency groups is potentially impacted. The flaw manifests in block cgroups that have a target latency and subsequently enter and exit the policy data lifecycle.
Risk and Exploitability
The EPSS score is listed as less than 1 %, indicating a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the defect can be triggered by any local process that manipulates blk‑iolatency policies, the risk is primarily local to privileged users or kernel module authors. While the impact is confined to I/O‑bound workloads within the affected cgroup, prolonged throttling can degrade overall system performance.
OpenCVE Enrichment